A Protective DNS Layer for Federal Civilian Networks
The Cybersecurity and Infrastructure Security Agency (CISA) has selected Cloudflare and Accenture Federal Services (AFS) to deliver a joint protective DNS resolver solution for the federal government. The offering will filter DNS queries originating from federal offices and locations, streaming event data to an Accenture analysis platform for threat monitoring and response.
CISA, which operates within the Department of Homeland Security, has long flagged the cyber risks associated with malicious hostnames and untrusted upstream DNS resolvers. Attackers routinely compromise systems by tricking users into resolving hostnames that lead to malware downloads, phishing pages, or data exfiltration channels. In May 2021, CISA and the National Security Agency jointly recommended that organizations deploy protective DNS resolvers as a countermeasure. Such resolvers do not simply return IP addresses for any requested hostname; they check each destination against known malicious or suspicious lists and block the connection when a match is found.
Earlier this year, CISA moved from recommendation to implementation, launching a program to offer protective DNS to its partners. After a review process, Cloudflare and AFS were selected to deliver the capability to departments and agencies of all sizes within the Federal Civilian Executive Branch.
Threat Landscape Motivates Action
The urgency of the program reflects a sustained increase in attacks against U.S. critical infrastructure. Cloudflare Radar consistently ranks the U.S. among the most targeted countries for DDoS attacks. Phishing campaigns compromise credentials to sensitive systems, while ransomware bypasses traditional network perimeters and takes down target systems.
Attack sophistication has also escalated. The SolarWinds Orion compromise demonstrated a supply chain attack where trusted software became a backdoor, with observed compromise patterns active over eight months and destinations growing to nearly 5,000 unique subdomains. CISA advised more than 6,000 state and local officials, as well as federal partners, on infrastructure protection mechanisms last year. Cloudflare saw a parallel demand trend: 229 state and local governments in 28 states used its Athenian Project services to defend election websites in 2020, with participation up 48% year over year.
Despite varied attack methods, a common denominator persists: attackers rely on DNS queries to malicious hostnames. From the SolarWinds campaign to spearphishing attacks against the U.S. Agency for International Development, the attack chain often begins with the same fundamental internet protocol used for legitimate traffic.
How Protective DNS Works
Standard internet activity begins with a DNS query. A browser, email client, or mobile app sends a query to convert a domain name into an IP address before establishing a connection. Attacks follow the same path—compromised devices generate queries to reach command-and-control infrastructure or leak data, and users visiting imposter sites may unknowingly participate in phishing schemes.

Conventional DNS resolvers trust all destinations by default; they return IP addresses without evaluating whether the requested hostname is suspicious. Known threats include hostnames from prior attacks or typosquatted domains, but new threats require behavioral analysis, pattern detection across query streams, and blocking of newly registered domains.
Protective DNS resolvers apply a Zero Trust model to DNS queries. Every query is checked against known malicious destination lists, and if the hostname or returned IP address appears on that list, the resolver withholds the result, causing the connection to fail.
Cloudflare Gateway and the Joint Solution
The CISA solution is built on Cloudflare Gateway, which routes DNS queries from enrolled devices and offices to Cloudflare's network. The protective DNS resolver supports encrypted DNS protocols, including DNS over HTTPS (DoH) and DNS over TLS (DoT).
Threat intelligence underpins the resolver's filtering decisions. Cloudflare's network handles more than 800 billion DNS queries daily and responds to 25 million HTTP requests per second across more than 200 cities in over 100 countries. This visibility feeds analysis that detects anomalies such as DNS tunneling, where hostnames are used to leak data. For the CISA deployment, Cloudflare's datasets are enriched with additional cybersecurity research and Accenture's Cyber Threat Intelligence (ACTI) feed to identify emerging threats. Data scientists apply advanced analytics powered by artificial intelligence and machine learning to further refine detection.
FedRAMP Pathway and Next Steps
Cloudflare recently announced that it is "In Process" in the Federal Risk and Authorization Management Program (FedRAMP) Marketplace. This status supports the broader adoption of Cloudflare's Zero Trust security solutions across federal agencies and complements the current contract award from CISA.
Cloudflare and Accenture Federal Services will now work together to deliver the protective DNS resolver to CISA, integrating the capability as part of a layered defense strategy for federal civilian networks. The solution is designed to be cost-efficient and accessible to government teams of varying sizes, aligning with CISA's mission to improve the security and reliability of critical infrastructure across the public sector.



